On Fri, Mar 07, 2008 at 12:49:45PM -0600, Nicolas Williams wrote: > On Fri, Mar 07, 2008 at 12:45:19PM -0600, Brian Cameron wrote: > > Nicholas: > > >I should note that making use of Solaris privileges to help build a > > >trusted path between the screen lock process and the X11 server would > > >mean that the screen lock process must run on the same system as the X11 > > >server because getpeerucred(3C) doesn't work remotely [yet]. > > > > But the Xserver also runs as the user. The login program does some > > handshaking with the Xserver to make it drop to user perms after > > the user authenticates. > > Not quite:
Of course, this is my desktop, which is running build 62, which is old. My laptop runs a much more recent build, but it's at home.